Unleash Productivity Lab

Privacy Policy

Unleash Productivity Lab (UPL)

Policy information

Policy information and details
Policy information Details
Canonical URL https://privacy.unleashproductivitylab.com/
Version UPL-PRIVACY-v1.0
Effective date 3 September 2026
Last updated 3 September 2026
Privacy contact privacy@unleashproductivitylab.com
General support +880 1886-163185

This table scrolls sideways on small screens.

1. Who we are

Unleash Productivity Lab (“UPL”, “we”, “our” or “us”) is a productivity education, coaching, community and business-transformation platform serving entrepreneurs, professionals, teams and small and medium enterprises. UPL’s activities may include free and paid resources, webinars, workshops, bootcamps, the Certified Systems Founder (CSF) Program, Systems Founders Guild, newsletters, assessments, consulting, customized implementation, managed automation and carefully governed AI-assisted services.

This Privacy Policy explains how UPL collects, uses, stores, discloses and protects personal information and how individuals can exercise their choices and rights. It should be read together with any program-specific notice, consent statement, service agreement, terms of use or data-processing agreement that applies to a particular service.

Back to top

2. Scope of this Policy

This Policy applies when a person interacts with UPL through:

  • UPL-owned websites, subdomains, landing pages and registration forms;
  • webinars, workshops, bootcamps, CSF, Guild, learning communities and events;
  • free resources, e-books, newsletters, assessments and downloads;
  • email, telephone, SMS, WhatsApp, Telegram, social media or support conversations;
  • payment, enrollment, attendance, assignment, certificate or service-interest processes;
  • consulting, customized services, managed automation and AI Business Assistant offerings;
  • surveys, testimonials, referrals, partnerships, recruitment or supplier relationships; and
  • analytics, security, system logs and other operational interactions with UPL systems.

A client organization may separately determine how personal information is processed within a solution UPL builds or manages for that client. In that situation, the client may be the data controller or responsible organization, and its own privacy notice may apply. UPL’s responsibilities will be governed by the applicable agreement and law.

Back to top

3. Information we may collect

Categories of information UPL may collect, with examples
Category Examples
Identity and contact Name, email address, mobile/telephone/WhatsApp number, organization, role, city/country and preferred language.
Registration and program Event/program selected, cohort, schedule, attendance, participation, assignments, progress, completion, certificate status, support needs and feedback.
Business and service Business profile, processes, objectives, challenges, requirements, systems, authorized users, service requests and implementation decisions.
Communication and consent Messages, inquiries, support records, channel preferences, opt-ins/opt-outs, consent wording/version, date/time, source page and withdrawal records.
Transaction Order, invoice, payment status, amount, refund status and limited transaction references. Payment-card/bank credentials should be handled by authorized payment providers, not stored by UPL unless clearly disclosed and required.
Content and submissions Survey answers, assignments, documents, recordings, testimonials, questions, comments and other material a person voluntarily provides.
Technical and usage IP address, device/browser, timestamps, page/referral data, cookies, session and security logs, message delivery status, workflow events and system performance.
AI interaction Prompts, instructions, uploaded material, generated outputs, feedback and tool/action records when an AI-assisted service is used.
Sensitive information Only when necessary, lawful, specifically disclosed and appropriately protected. Please do not send unnecessary passwords, financial credentials, health data, government IDs or other sensitive data through ordinary chat or forms.

This table scrolls sideways on small screens.

Back to top

4. How we collect information

We may collect information directly from the individual; from an organization that authorizes or enrolls the individual; from UPL forms, websites and communication channels; from payment, messaging, learning, meeting and service providers; from integrations and automation workflows; from cookies/analytics; and from publicly available or lawfully supplied business sources. Where information comes from another person or organization, that provider is responsible for having authority to share it.

Back to top

5. Why we use personal information

Purposes of processing and typical activities
Purpose Typical activities
Deliver a requested service Register a person, confirm enrollment, provide joining/access information, deliver resources, administer learning, provide support and complete requested work.
Essential communication Send confirmations, schedule changes, reminders, access links, assignment/service notices, security messages and necessary follow-up for the requested event, program or service.
Relationship and records Maintain contact, registration, attendance, learning, service, consent, transaction and support histories; prevent duplicates; and preserve operational continuity.
Personalization and improvement Tailor content or support, understand demand, measure outcomes, improve journeys, troubleshoot defects and develop relevant offerings.
Marketing with appropriate choice Send newsletters, resources, program information and offers where consent or another lawful basis permits; honor opt-out and channel preferences.
Payment and administration Process fees/refunds, issue invoices/receipts, reconcile records, manage contracts and meet accounting obligations.
Security and integrity Authenticate users, control access, prevent fraud/abuse, investigate incidents, back up systems and maintain audit trails.
Legal and protective Comply with law, respond to lawful requests, establish or defend rights, enforce terms and protect UPL, participants, clients and the public.
Automation and AI assistance Route requests, schedule communications, generate drafts/summaries, retrieve authorized information and support controlled actions as described in Section 10.

This table scrolls sideways on small screens.

UPL will not use personal information for a materially incompatible new purpose without providing an appropriate notice and obtaining consent or another lawful basis where required.

Back to top

7. Email, SMS, WhatsApp, Telegram and other communications

UPL may use the channels supplied or selected by an individual to provide requested confirmations, reminders, links, resources, support and operational notices. Optional promotional communication will follow the consent and preference applicable to that channel and purpose.

  • Email recipients may use the unsubscribe mechanism or contact UPL.
  • A person may reply with an available opt-out instruction or contact UPL to stop optional SMS/WhatsApp communication.
  • Leaving a WhatsApp/Telegram group may not remove a person from every separately consented list; contact UPL for complete preference changes.
  • Opt-out requests may take a reasonable period to propagate across connected systems. A suppression record may be retained to avoid contacting the person again.
  • Channel providers process metadata and content under their own terms and privacy practices. Individuals should avoid sending sensitive credentials through ordinary messages.
Back to top

8. Cookies, analytics and similar technologies

UPL websites may use essential cookies or local storage needed for security, form continuity, preferences and basic functionality. With appropriate notice or consent where required, UPL may also use analytics, advertising or measurement technologies to understand traffic, campaign performance and user experience.

A cookie banner or preference tool should identify non-essential categories before activation. Browser controls may limit cookies, but disabling essential storage may affect functionality. UPL will update this section and its cookie notice when analytics or advertising tools change.

Back to top

9. Payments

Payments may be processed by banks, mobile financial services, payment gateways or other authorized providers. UPL may receive transaction status, amount, payer/contact details and a reference necessary for enrollment, reconciliation, refund, fraud prevention and accounting. Unless specifically disclosed and securely arranged, UPL does not seek to store full payment-card numbers, banking passwords, PINs or one-time passwords. Individuals must never send such credentials to UPL staff, bots or ordinary forms.

Back to top

10. Automation, profiling and artificial intelligence

UPL uses automation to reduce repetitive work, coordinate customer and learning journeys, maintain records, schedule permitted messages, detect failures and prepare reports. UPL may use AI-assisted tools to create drafts, summaries, recommendations, educational content, support responses, analysis or conversational assistance.

  • AI output can be incomplete or incorrect and should be reviewed according to its importance.
  • UPL does not intend to let AI make final high-impact decisions about payment, legal rights, disciplinary action, graduation/certification, employment, sensitive eligibility or similar matters without accountable human oversight.
  • AI agents and automation tools receive only the access reasonably required for approved functions, with controls, logs and approval gates proportionate to risk.
  • Clients and users must not place unnecessary confidential information, passwords or third-party personal data into an AI service.
  • Where UPL manages automation or an AI assistant for a client, roles, permitted data, access, human approvals, retention, suspension and offboarding should be defined by contract.
  • UPL may temporarily suspend an AI function, tool or communication route for security, misuse, non-payment, maintenance, legal or risk-control reasons, subject to the applicable agreement.
Back to top

11. When we disclose information

UPL does not sell personal information. UPL may disclose the minimum necessary information to:

  • service providers supporting hosting, cloud storage, forms, productivity tools, email, SMS, WhatsApp/Telegram, video meetings, payment, analytics, security, automation, AI/model processing and customer support;
  • authorized UPL staff, trainers, facilitators, contractors and professional advisers who need access and are subject to appropriate duties;
  • a client or sponsoring organization where the person participates through that organization and disclosure is appropriate and disclosed;
  • law-enforcement, courts, regulators or other authorities where required or lawfully requested;
  • a successor or transaction party in a merger, restructuring, financing or transfer, subject to appropriate confidentiality and lawful safeguards; and
  • another party where the individual directs, authorizes or reasonably expects the disclosure in the stated context.

Providers may change as UPL improves its systems. UPL will evaluate providers according to function, security, privacy, contractual and operational needs and will update material disclosures when required.

Back to top

12. International processing and transfers

Some service providers or their infrastructure may operate outside Bangladesh. This can result in information being stored, accessed or processed in another country with different laws. Where cross-border processing occurs, UPL will use measures required by applicable law and proportionate contractual, technical and organizational safeguards. A person may contact UPL for information about relevant categories of recipients and safeguards, subject to security and confidentiality limitations.

Back to top

13. Data security

UPL uses reasonable administrative, technical and organizational measures proportionate to the nature and risk of the information. These may include access control, named accounts, least privilege, authentication, encryption where appropriate, secure configuration, logging, monitoring, backups, testing, patching, incident response, credential rotation, staff guidance and separation of client environments.

No website, messaging platform, cloud service, transmission or storage system is completely secure. UPL therefore cannot promise absolute or “100%” security. Individuals are responsible for protecting their own devices, accounts and credentials and for promptly reporting suspected misuse.

Back to top

14. Retention and deletion

UPL retains personal information only for as long as reasonably needed for the stated purpose, contractual and operational continuity, consent/suppression evidence, security, dispute handling, accounting and legal obligations. Retention may vary by record type and applicable agreement.

Record types and the corresponding retention approach
Record type Retention approach
Uncompleted inquiry / unconverted lead Up to 24 months after the last meaningful interaction, unless consent is withdrawn earlier or a longer period is justified.
Event/webinar registration and attendance Up to 36 months for program records, analysis and follow-up consistent with consent.
Student/member/program record Duration of participation plus up to 7 years where needed for certification, disputes, accounting or legitimate records.
Transaction, invoice and accounting At least the period required by applicable tax/accounting law; operational target up to 7 years.
Optional marketing profile Until opt-out, invalid contact or prolonged inactivity under UPL’s suppression/retention process.
Consent, withdrawal and suppression evidence For the relevant processing period plus a reasonable period needed to demonstrate compliance and honor the choice.
Support and service records Contract/service period plus up to 3 years, or longer for unresolved claims/security requirements.
Security, workflow and access logs Normally 90 days to 24 months depending on risk, system and contractual need.
Backups Rotating schedule; deleted data may remain until backup expiry and should not be restored to active use except for recovery.
AI conversation/content According to the stated feature, provider settings and contract; minimize by default and define shorter limits for sensitive use.

This table scrolls sideways on small screens.

These retention periods are general operational guidelines. They may be shortened or extended when applicable law, a contract, a dispute, a security incident, a legal hold or a documented operational need requires.

When information is no longer required, UPL may delete, anonymize, aggregate or securely isolate it. Some minimal records may be retained to honor opt-outs, demonstrate consent/transactions, prevent fraud or establish legal rights.

Back to top

15. Individual rights and choices

Subject to applicable law, identity verification, exceptions and the context, an individual may request to:

  • know whether and how UPL processes their personal information;
  • access or receive a copy of relevant personal information;
  • correct inaccurate or incomplete information;
  • withdraw consent for future consent-based processing;
  • stop optional marketing or change channel preferences;
  • request deletion, restriction or objection where applicable;
  • request portability where applicable and technically feasible;
  • ask for information about significant automated processing; and
  • raise a concern or complaint.

Submit a request to privacy@unleashproductivitylab.com with enough information to identify the relevant relationship and request. UPL may ask for reasonable identity verification and will not disclose information where doing so would compromise another person’s privacy, security, confidential business information or legal rights. UPL will acknowledge and respond within the period required by applicable law or, where no specific period applies, within a reasonable time.

Back to top

16. Children and young people

UPL’s business, founder and professional programs are generally intended for adults. UPL does not knowingly seek personal information from a child for services requiring adult participation without appropriate parent/guardian involvement and any consent required by law. If a parent or guardian believes a child has provided information improperly, they should contact UPL so that it can investigate and take appropriate action.

Back to top

17. Recordings, photographs and testimonials

UPL may record an event, class, meeting or testimonial only with an appropriate notice and any permission required for the intended use. Attendance in an online session does not automatically grant unlimited promotional rights over a participant’s image, voice, name or story. UPL should offer reasonable camera/display options where feasible and obtain separate, specific permission before publishing an identifiable testimonial or promotional feature. Permission may be subject to agreed usage already lawfully completed before withdrawal.

Back to top

19. Client automation and managed services

When UPL designs, deploys or supports automation for a business client, client data should remain logically and operationally separated from other clients. The client should own or control its production accounts, credentials and business data, while UPL receives only documented support access necessary for its role. UPL and the client will determine their respective privacy responsibilities in a service and data-processing agreement.

UPL may retain ownership of generic templates, deployment tools and operating methods without acquiring ownership of the client’s personal data. Production changes, access, monitoring, backups, incident responsibilities, retention, exports and offboarding should be recorded contractually. Disabling an optional AI assistant should not automatically stop a client’s core business automation unless the contract and architecture expressly require it.

Back to top

20. Confidentiality and acceptable use

This Policy does not authorize any user to upload or disclose information they do not have the right to provide. Users and clients must avoid transmitting third-party data, confidential documents, copyrighted material, credentials or regulated information unless the relevant UPL service expressly supports it and appropriate authority, notice, consent and safeguards exist. UPL may reject, isolate, remove or restrict information or access where reasonably necessary to protect people, systems, legal rights or service integrity.

Back to top

21. Data incidents

UPL maintains a process to identify, contain, investigate and recover from suspected personal-data incidents. Where notification is required by applicable law or contract, UPL will notify the appropriate parties within the required manner and timeframe, based on available verified information. UPL may preserve relevant evidence and cooperate with providers, clients, authorities and affected individuals as appropriate.

Back to top

22. Changes to this Policy

UPL may update this Policy when its services, systems, providers, laws or practices change. The current version will be published at the canonical URL with a “Last updated” date and version number. Material changes may also be communicated through an appropriate channel. Where a change requires new consent, UPL will seek it before relying on that consent for the new purpose.

Back to top

23. Contact us

For a privacy question, request, correction, consent withdrawal or complaint, contact:

Contact points and details
Contact Details
Organization Unleash Productivity Lab (UPL)
Privacy email privacy@unleashproductivitylab.com
General support +880 1886-163185
Privacy page https://privacy.unleashproductivitylab.com/
Postal/legal address To be added if/when UPL confirms an official public service address

This table scrolls sideways on small screens.

Please do not send passwords, PINs, one-time passwords, full card numbers or unnecessary sensitive information in an initial privacy request.

Back to top